Forensic Analysis of 7-Zip Archive Metadata
Digital forensics investigators frequently examine 7-Zip (.7z) archives to uncover evidence of data exfiltration, malware staging, and file tampering. This article details how investigators locate, extract, and interpret metadata embedded within the 7-Zip container format, explaining the technical structure of 7z headers, the critical timestamps and attributes preserved during compression, and the methodologies used to analyze both cleartext and encrypted archives.
The Architecture of 7-Zip Metadata
Unlike standard ZIP files that store metadata in local file headers
preceding each compressed file, the 7-Zip format consolidates metadata
into dedicated header structures. A standard .7z file
begins with a 32-byte Start Header that contains a specific signature
(37 7A BC AF 27 1C), version information, and a relative
offset pointing to the Main Header (often called the End Header).
The Main Header contains the complete metadata catalog for the archive, including:
- File Hierarchy: Original filenames, directory paths, and folder structures.
- Stream Descriptors: Uncompressed sizes, packed sizes, and compression method identifiers (e.g., LZMA, LZMA2, PPMd, BZip2).
- Data Integrity Values: CRC-32 checksums for each individual stream.
- File Attributes: Standard Windows/DOS attributes (such as Read-Only, Hidden, System, and Archive flags).
Extracting Forensic Timestamps
7-Zip preserves high-resolution timestamps, which are critical for
building digital forensic timelines. By default, 7-Zip stores timestamps
in the Windows FILETIME structure—a 64-bit value
representing 100-nanosecond intervals since January 1, 1601 (UTC).
Investigators analyze up to three distinct timestamps per file:
- Last Modified Time (MTime): Included by default in most 7-Zip archives.
- Creation Time (CTime): Captured if the archive was created using specific switches or modern GUI versions configured to preserve complete time records.
- Last Access Time (ATime): Preserved conditionally depending on the host operating system's settings and creation flags.
Forensic practitioners compare these internal timestamps against the
external file system timestamps of the .7z container
itself. A discrepancy where internal files have creation or modification
times newer than the container’s creation time suggests archive
manipulation, container copying, or potential timestomping.
Methods and Tools for Metadata Extraction
Investigators rely on both native command-line utilities and specialized digital forensics platforms to parse metadata without modifying the original evidence.
Technical Command-Line Extraction
The 7-Zip command-line tool provides a raw, structured dump of all
metadata using the -slt (Show Technical Information)
switch:
7z l -slt target_archive.7zThis output displays the exact compression method, physical block sizes, characteristics, CRC values, and complete 64-bit timestamps for every entry.
Automated Forensic Suites
Tools such as Magnet AXIOM, OpenText EnCase, and Autopsy automatically parse 7-Zip containers during ingestion. These suites parse the central header, extract individual file entries into the case database, and populate the master timeline with internal metadata, allowing investigators to correlate compressed file activity with system logs and registry events.
Low-Level Hex and Python Parsing
When an archive is damaged, truncated, or subjected to anti-forensic
wiping, examiners parse raw byte sequences using hex editors or
libraries like py7zr. Investigators search for the
kEnd marker (0x00) and metadata property IDs
(such as kCTime [0x13], kMTime
[0x14], and kWinAttributes
[0x15]) to manually reconstruct archive contents when
headers cannot be automatically read.
Investigating Encrypted Archives
7-Zip supports AES-256 encryption in two modes, each presenting different investigative scenarios:
- Standard Payload Encryption: The compressed data streams are encrypted, but the Main Header remains unencrypted. In this state, investigators can view all metadata—including file names, directory trees, file sizes, and timestamps—without requiring the decryption password. This allows examiners to prove that sensitive data was staged even if the file contents cannot be decrypted.
- Header Encryption (
-mhe=on): Both the data streams and the Main Header are encrypted. The initial 32-byte Start Header remains visible, indicating the archive type and encryption parameters, but all file names, timestamps, and attributes are hidden. In this scenario, examiners must recover the passphrase through memory analysis (extracting keys from process memory), credential harvesting, or targeted password recovery attacks before any metadata can be parsed.